CVE-2025-15112

Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kseniasecurity:lares_firmware:1.6:*:*:*:*:*:*:*
cpe:2.3:h:kseniasecurity:lares:4.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-30 23:15

Updated : 2026-01-16 19:16


NVD link : CVE-2025-15112

Mitre link : CVE-2025-15112

CVE.ORG link : CVE-2025-15112


JSON object : View

Products Affected

kseniasecurity

  • lares
  • lares_firmware
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')